# Critical HVAC and UPS Vulnerabilities Expose Data Centers to Remote Disruption Attacks


Claroty researchers have uncovered multiple critical security flaws in widely-deployed infrastructure systems that power data centers worldwide, revealing a dangerous vulnerability chain that could allow attackers to remotely disable cooling systems and power management—potentially causing millions in damage and widespread service outages.


## The Threat


Security researchers at Claroty, a cyber-physical systems specialist, have identified critical vulnerabilities in two essential data center systems:


Vertiv UPS Network Cards:

  • Authentication bypass flaw allowing unauthorized access
  • Remote code execution (RCE) vulnerability enabling arbitrary command execution
  • Chaining both flaws permits complete compromise of UPS devices
  • Affects network interface cards designed to provide web-based management

  • Trane Tracer SC+ HVAC Controller:

  • Authentication bypass vulnerability
  • Remote code execution capabilities
  • Denial of service (DoS) flaws
  • Sensitive information disclosure issues
  • Allows unauthenticated remote access to building management systems

  • The combination of these vulnerabilities represents a critical risk: an attacker with network access could simultaneously disable both power protection and cooling systems in a data center—a one-two punch that could trigger catastrophic cascading failures.


    ## Background and Context


    The implications of these vulnerabilities extend far beyond a simple system outage. Understanding the role of these systems in data center operations is essential:


    Uninterruptible Power Supplies (UPS) serve critical functions:

  • Maintain operations during power outages
  • Protect equipment from power spikes and voltage fluctuations
  • Enable graceful system shutdowns
  • Form the backbone of data center redundancy

  • According to Claroty, "In large data centers, virtually all computing equipment relies on UPS devices to stay online during power issues. Any weakness in those UPS communication modules can directly affect the machines they protect."


    HVAC systems are equally vital:

  • Data center servers generate enormous quantities of heat
  • Modern facilities operate with minimal thermal margins
  • HVAC failure triggers equipment thermal shutdowns within minutes
  • Cascading failures can damage expensive hardware permanently

  • The attack surface is particularly concerning because these devices are typically connected to facility networks—often with minimal network segmentation or monitoring. Many organizations treat environmental controls as non-critical from a cybersecurity perspective, making them attractive targets for attackers seeking to disrupt operations without triggering traditional security alerts.


    ## Technical Details


    The Vertiv Attack Chain:


    The vulnerability chain in Vertiv's network cards works as follows:


    1. Authentication Bypass — The web interface protecting UPS management functions fails to properly validate credentials, allowing unauthorized access to administrative features

    2. Remote Code Execution — Once inside, attackers can execute arbitrary commands on the network card itself

    3. Operational Impact — Full control of the UPS enables attackers to:

    - Disable power protection for connected equipment

    - Trigger emergency shutdown sequences

    - Manipulate power distribution to specific equipment

    - Alter monitoring and alerting systems


    The Trane HVAC Vulnerabilities:


    The Trane Tracer SC+ controller exhibits a similar pattern but with even broader implications:


    | Vulnerability | Impact | Severity |

    |---|---|---|

    | Authentication Bypass | Unauthenticated administrative access | Critical |

    | Remote Code Execution | Full system compromise | Critical |

    | Information Disclosure | Exposure of building layout, sensor data, configurations | High |

    | Denial of Service | System crashes or resource exhaustion | High |


    Claroty emphasized that "data center servers generate enormous amounts of heat, and an HVAC failure is far more than a comfort issue. It can trigger thermal shutdowns, damage expensive hardware, cause major service disruptions, and lead to millions of dollars in losses."


    ## Implications for Organizations


    Immediate Risks:


  • Data center operators managing large facilities depend entirely on these systems; a successful attack could trigger cascading outages affecting thousands of customers
  • Cloud providers using Vertiv and Trane systems are exposed to attacks that could affect entire regions
  • Enterprise facilities hosting critical infrastructure face similar thermal and power protection risks
  • Healthcare facilities (many of which operate data centers for patient records) face heightened risk due to regulatory compliance and patient safety implications

  • Attack Scenarios:


    A realistic attack progression might look like this:


    1. Attacker gains initial network access through phishing or vulnerable web services

    2. Reconnaissance identifies Vertiv or Trane devices on facility network

    3. Authentication bypass exploits provide immediate administrative access

    4. Attacker executes code to disable HVAC or alter UPS behavior

    5. Equipment thermal shutdown or power loss cascades across facility

    6. Extended recovery period impacts business operations


    The financial impact could be severe: major data center outages cost $5,600 per minute to large enterprises, meaning even a 30-minute incident could exceed $168,000 in damages, not accounting for lost reputation and customer churn.


    ## Recommendations for Defenders


    Immediate Actions:


  • Patch Management — Apply security updates from Vertiv and Trane immediately upon release
  • Network Segmentation — Isolate UPS and HVAC management systems on separate network segments with restricted access controls
  • Credential Hardening — Change default credentials on all UPS and HVAC devices; implement strong authentication
  • Access Logging — Enable detailed audit logging on management interfaces to detect unauthorized access attempts

  • Strategic Controls:


  • Out-of-Band Monitoring — Implement independent monitoring of critical environmental parameters that doesn't rely on potentially compromised management systems
  • Redundancy Review — Assess failover capabilities; ensure secondary systems can maintain operations if primary management systems are compromised
  • Facility Network Audit — Map all connected devices; identify unnecessary network paths to environmental control systems
  • Incident Response Planning — Develop specific procedures for responding to environmental system compromise

  • ---


    ## HackWire Analysis


    This vulnerability disclosure represents a troubling pattern in industrial control system security: attackers have increasingly recognized that environmental controls offer a path to operational disruption that bypasses traditional network security. Unlike applications that require user interaction to exploit, HVAC and power systems sit passively on facility networks, often overlooked in security assessments.


    What makes this moment particularly critical is the convergence of automation and underestimation. Data center operators have grown accustomed to thinking of cooling and power as solved problems—ancient infrastructure that "just works." But the digitization of these systems has created a new attack surface that most organizations haven't adequately secured. The default web interfaces, the legacy authentication schemes, and the assumption that "no one would target these systems"—this is exactly where attackers focus.


    Consider the broader context: we've seen ransomware groups target hospital HVAC systems, criminal syndicates compromise building management systems in corporate headquarters, and nation-state actors conduct reconnaissance on critical infrastructure SCADA systems. This research from Claroty suggests those patterns aren't aberrations—they're reconnaissance for what might come next.


    For defenders, the concrete next steps are clear: treat environmental controls with the same security rigor as your production systems. These aren't comfort features—they're availability features. A facility without cooling isn't a facility; it's a fire hazard. Organizations should begin with a simple inventory: identify every Vertiv and Trane device in your environment, verify patch status, and implement network segmentation. The vendors have provided patches; organizations now have the tools to protect themselves. The question is whether they'll act before attackers do.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Critical Infrastructure](https://www.hackwire.news/category/critical-infrastructure) and [Industrial Control Systems](https://www.hackwire.news/category/industrial-control-systems)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)